CVE-2026-54051
Network‑AI, a TypeScript/Node.js orchestrator, had a flaw that let attackers run arbitrary shell commands through the agent sandbox. The bug was caused by a permissive allowlist that matched whole command strings and then executed them via /bin/sh. The issue is fixed in version 5.9.1.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Network‑AI orchestrator, versions prior to 5.9.1, used by developers and operations teams running multi‑agent workflows.
Real-world impact
An attacker who compromises an agent could run any shell command on the host, giving them full control over the system.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability is network‑reachable, requires low effort, and allows an attacker to gain complete confidentiality, integrity, and availability of the affected system.
What to do about it
- 01Upgrade Network‑AI to version 5.9.1 or later.
NVD-referenced vendor advisory
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.